Three settings, three jobs
These three settings don't replace one another; they work together.
| Setting | What it does | If it's missing |
|---|---|---|
| SPF | Lists which servers are allowed to send email in your name | Other servers can send email in your name, and your email looks suspicious |
| DKIM | Adds a digital signature tied to your domain to every message | There's no proof the message wasn't altered on the way |
| DMARC | Says what to do with email that fails SPF and DKIM, and sends reports | Fake email isn't blocked, and you can't see who is using your name |
SPF record
SPF is a single TXT record added to your domain's DNS. For example, if only your own mail server and a newsletter tool send email, the record looks roughly like v=spf1 mx include:newsletter-tool.com ~all. Common mistakes here are having two separate SPF records on the same domain, leaving sending systems such as invoicing software or a CRM off the list, and adding so many includes that the record goes over its limit.
DKIM signature
For DKIM, your mail server generates a key pair. The private key stays on the server, and the public key is added to DNS as a TXT record. Every outgoing email is signed, and the receiving server verifies the signature against the key in DNS. If more than one system sends email in your name, each of them needs its own DKIM setup.
DMARC policy
The DMARC record is added under the name _dmarc, and moving in stages is the safest approach:
- Monitoring. You start with
v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.com; no email is blocked, reports are simply collected. - Quarantine. Once the reports confirm all legitimate sending sources,
p=quarantinesends failing email to spam. - Reject. If everything looks good,
p=rejecthas fake email rejected outright.
This sequence keeps an overlooked sending source (for example, automatic invoice emails from your accounting software) from suddenly being blocked.
Why can't this wait any longer?
Since 2024, Google and Yahoo have expected SPF, DKIM and DMARC together, especially from domains that send email in high volumes; other major providers have taken similar steps. Even for companies that send little email, these settings directly affect delivery rates. On top of that, DMARC is the most effective technical safeguard against fraud attempts that send fake payment requests in your company's name.
Checklist
- Does the domain have a single SPF record that includes all sending sources?
- Do the mail server and other sending tools sign with DKIM?
- Is there a DMARC record, and are the reports being read?
- Have protective records been added for your secondary domains that don't send email?
Frequently asked questions
Once these are set up, will our email never land in spam?
Delivery rates improve noticeably, but content, sending frequency and server reputation also matter. Identity settings are a basic requirement, not the only factor.
Do these settings affect our website?
No. These records concern email only; they don't affect how your website works.
For general DNS management, see the domain and SSL page; for the big picture, see the business email page, or reach out to us to have your domain checked.